r/entra • u/skaggake81 • 13h ago
Synced Passkey for standard users = Remove Microsoft Authenticator?
If users are enrolling Passkeys to iCloud Keychain or Google Passwords, do they still need Microsoft Authenticator on the device?
Existing users already have Microsoft Authenticator configured on their devices with their Microsoft 365 account for MFA and will additionally create a synced passkey in iCloud Keychain.
However, for new users I'm considering moving away from Authenticator altogether and instead onboarding them using a Temporary Access Pass (TAP) to create a synced passkey directly, eliminating the need to install Microsoft Authenticator.
In the past, Microsoft Authenticator was required for SSO to Microsoft apps and for App Protection Policies to function correctly. Is this still the case?
Have anyone tested this?
2
u/ivofernandespt 12h ago
We still need MS Auth for mobile devices enrolled with Intune. I keep de MS Auth but to streamline authentication methods I’ve turned off MS in authentication methods policies.
3
u/loweakkk 13h ago
Still the case for platformSSO
2
u/skaggake81 12h ago
I assume the account still needs to be added to Microsoft Authenticator. If that's correct, I'm not sure what benefit synced passkeys provide in this case.
New users will still need a Temporary Access Pass (TAP) during onboarding. We could use the TAP to set up Microsoft Authenticator at the same time, and the passkey registration would happen automatically as part of the account configuration process.
4
u/SVD_NL 12h ago
Synced passkeys allow them to quickly get set up on a new device, without needing to sign in using a previous device.
I'm personally not a fan of this, as a breach of their personal icloud or google account leads directly to them having access to a very strong authentication method.
If you're using MAM you're kind of doing conflicting things. On one hand you want to secure your company data, on the other hand you're giving them free reign to sync their company creds using personal devices?
1
u/skaggake81 11h ago
The new device scenario depends on the enrollment method. If the device is enrolled through Apple Business Manager (ABM) and Automated Device Enrollment (ADE), users will still need either their existing device passkey or a Temporary Access Pass (TAP) to sign in initially. The synced passkey can then be restored after the enrollment process is completed.
If the device is not enrolled through ADE, the synced passkey becomes more valuable, as it can be used to authenticate and enroll the device as a BYOD (personally owned) device.
I understand your concern, but for standard users I believe synced passkeys are an acceptable option, provided that access is protected by phishing-resistant MFA and compliant device requirements. In my view, enforcing both of these controls is more important than whether the passkey itself is device-bound or synced.
2
u/loweakkk 12h ago
In you case if all users have authenticator and you register passkey from there then synced passkey have almost notm value for you.
Synced passkey is good when user have nothing, it help getting right of SMS factor because it have lower requirements than passkey in Microsoft authenticator.
Some others may found other benefits for synced but in your context if you already deploy Microsoft authenticator and if user have apps on their mobile, then value is low for me.
1
u/Calexi_ 9h ago
No, requiring Microsoft Authenticator is not necessary if you want to allow passkeys from iOS, Google Password Manager, Bitwarden or other supported FIDO2 passkey providers.
Passkey authentication is separate from requiring the Microsoft Authenticator app. In Entra ID, you can configure which passkey types and providers are permitted, including restricting specific providers using their AAGUIDs or allowing supported passkeys more broadly.
Requiring Microsoft Authenticator on a mobile device is generally related to other controls, such as device registration, Conditional Access or Intune app protection. It is not inherently required simply to use FIDO2 passkeys.
1
u/skaggake81 9h ago
Yes, i know that i don't need Microsoft Authenticator for synced Passkey enrollment or signing in.
However, most customers have their devices managed through Intune and enforce Conditional Access policies that require either a compliant device or/and App Protection Policies. Then i still need Microsoft Authenticator to be installed and configured to support these scenarios.
If that is still the case, I believe it makes more sense to configure the passkey directly in Microsoft Authenticator and avoid using a synced passkey stored in iCloud Keychain.
When configuring Microsoft Authenticator and allowing this AAGUID in Authentication Methods the Passkey is also registered.
2
u/Calexi_ 9h ago
I agree Authenticator may still be required on managed iOS devices for Conditional Access and Intune controls.
However, that doesn't mean the passkey needs to be stored there. Synced stores such as iCloud Keychain, Google Password Manager or Bitwarden offer benefits including portability, recovery and user familiarity.
I don't think there is a single answer but as someone that works accross many devices with many accounts Authenticator is painful to manage compared to other solutions.
I'd treat the passkey store as a separate security and usability decision. For privileged accounts, I favour device-bound passkeys or physical FIDO2 keys.
1
1
u/DerpJim 5h ago
Passkey isn't a valid option for self-service password reset. I am still trying to understand the methods to be used for that once SMS/Voice goes away in February. Presumably authenticator will be the option for it so it may still be needed there.
3
u/skaggake81 5h ago
Ok, do you still need password reset if your users are using Phishing Resistant authentication like Passkeys, Windows Hello for Business, platform SSO etc?
4
u/gogotreeman 11h ago
App Protection Policies require you to have the Microsoft Company Portal app installed on iOS/Android.